2 ms·
> The attacker can't know if they passed the captcha until an hour has passed. Naah. The attacker just does batch learning: dump a ton of comments, wait an ho
by bin0 7y ago
> The attacker can't know if they passed the captcha until an hour has passed.
Naah. The attacker just does batch learning: dump a ton of comments, wait an hour, spend a few minutes training, rinse-and-repeat. Your users also won't tolerate tons of delays.
> You can then slow it down further with some randomization.
So now I wait a few extra hours, and have 99% accurate data. That's still pretty good, honestly. Ideally, a neural network can get a good model from less accurate data than 99%; just tweak the learning rate or use sgd, modify mini-batch size, etc.
The advantage of the site, of course, is that legitimate businesses are likely more able to afford people with this sort of knowledge. The scammers are probably script kiddies who clone a template and tweak a config; they'd have real jobs if they knew more.